US12438708B2ActiveUtilityA1

System and method for eliminating potential security breach when transitioning to quantum-secure environment

Assignee: ARISTA NETWORKS INCPriority: Dec 19, 2023Filed: Dec 19, 2023Granted: Oct 7, 2025
Est. expiryDec 19, 2043(~17.4 yrs left)· nominal 20-yr term from priority
H04L 9/0852
46
PatentIndex Score
0
Cited by
1
References
20
Claims

Abstract

A physical link is split between network devices into a first logical link and a second logical link. The first logical link is designated for communicating user data. The second logical link is designated for exchanging key identifiers (key IDs) only. The second logical link is left open and unencrypted and the key IDs are exchanged over the second logical link. Using the key IDs, quantum keys are acquired, by an agent on each respective network device, from a quantum key distribution network or subsystem. The quantum keys thus acquired are then applied to the physical link between the network devices to thereby transition the physical link between the network devices to a quantum-secure environment and open the first logical link for communicating the user data in the quantum-secure environment.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. A method, comprising:
 configuring a link for communicating user data between network devices with static keys that do not match, wherein any transmission of the user data over the link is initially blocked because the static keys do not match and continues to be blocked until quantum keys can be applied to encrypt network traffic communicated over the link; 
 exchanging key identifiers of the quantum keys over the link; 
 acquiring the quantum keys from a quantum key distribution subsystem using the key identifiers; and 
 applying the quantum keys to encrypt the network traffic communicated over the link between the network devices to thereby unblock the transmission of the user data and transition the link between the network devices to a quantum-secure link. 
 
     
     
       2. The method according to  claim 1 , further comprising:
 splitting the link between the network devices into a first logical link and a second logical link; 
 designating the first logical link for communicating the user data between the network devices; and 
 designating the second logical link for exchanging the key identifiers of the quantum keys, wherein the second logical link is left open and unencrypted. 
 
     
     
       3. The method according to  claim 2 , wherein the first logical link comprises a data link and wherein the second logical link comprises a control link. 
     
     
       4. The method according to  claim 2 , wherein the first logical link comprises a first virtualized connection and wherein the second logical link comprises a second virtualized connection. 
     
     
       5. The method according to  claim 1 , wherein each of the network devices comprises a secure application entity (SAE), wherein the SAE runs a MACSec/QKD configuration software application that allows deployment of MACSec links with the quantum key distribution subsystem, and wherein the SAE comprises an application configured for exchanging the key identifiers, acquiring the quantum keys from the quantum key distribution subsystem using the key identifiers, and applying the quantum keys to the link between the SAEs. 
     
     
       6. The method according to  claim 1 , wherein the quantum key distribution subsystem comprises a key management entity (KME) configured for quantum key generation and distribution. 
     
     
       7. The method according to  claim 1 , wherein the link comprises a Media Access Control security (MACSec) link. 
     
     
       8. A system, comprising:
 a processor; 
 a non-transitory computer-readable medium; and 
 instructions stored on the non-transitory computer-readable medium and translatable by the processor for:
 configuring a link for communicating user data between network devices with static keys that do not match, wherein any transmission of the user data over the link is initially blocked because the static keys do not match and continues to be blocked until quantum keys can be applied to encrypt network traffic communicated over the link; 
 exchanging key identifiers of the quantum keys over the link; 
 acquiring the quantum keys from a quantum key distribution subsystem using the key identifiers; and 
 applying the quantum keys to encrypt the network traffic communicated over the link between the network devices to thereby unblock the transmission of the user data and transition the link between the network devices to a quantum-secure link. 
 
 
     
     
       9. The system of  claim 8 , wherein the instructions are further translatable by the processor for:
 splitting the link between the network devices into a first logical link and a second logical link; 
 designating the first logical link for communicating the user data between the network devices; and 
 designating the second logical link for exchanging the key identifiers of the quantum keys, wherein the second logical link is left open and unencrypted. 
 
     
     
       10. The system of  claim 9 , wherein the first logical link comprises a data link and wherein the second logical link comprises a control link. 
     
     
       11. The system of  claim 9 , wherein the first logical link comprises a first virtualized connection and wherein the second logical link comprises a second virtualized connection. 
     
     
       12. The system of  claim 8 , wherein each of the network devices comprises a secure application entity (SAE), wherein the SAE runs a MACSec/QKD configuration software application that allows deployment of MACSec links with the quantum key distribution subsystem, and wherein the SAE comprises an application configured for exchanging the key identifiers, acquiring the quantum keys from the quantum key distribution subsystem using the key identifiers, and applying the quantum keys to the link between the SAEs. 
     
     
       13. The system of  claim 8 , wherein the quantum key distribution subsystem comprises a key management entity (KME) configured for quantum key generation and distribution. 
     
     
       14. The system of  claim 8 , wherein the link comprises a Media Access Control security (MACSec) link. 
     
     
       15. A computer program product comprising a non-transitory computer-readable medium storing instructions translatable by a processor for:
 configuring a link for communicating user data between network devices with static keys that do not match, wherein any transmission of the user data over the link is initially blocked because the static keys do not match and continues to be blocked until quantum keys can be applied to encrypt network traffic communicated over the link; 
 exchanging key identifiers of the quantum keys over the link; 
 acquiring the quantum keys from a quantum key distribution subsystem using the key identifiers; and 
 applying the quantum keys to encrypt the network traffic communicated over the link between the network devices to thereby unblock the transmission of the user data and transition the link between the network devices to a quantum-secure link. 
 
     
     
       16. The computer program product of  claim 15 , wherein the instructions are further translatable by the processor for:
 splitting the link between the network devices into a first logical link and a second logical link; 
 designating the first logical link for communicating the user data between the network devices; and 
 designating the second logical link for exchanging the key identifiers of the quantum keys, wherein the second logical link is left open and unencrypted. 
 
     
     
       17. The computer program product of  claim 16 , wherein the first logical link comprises a data link and wherein the second logical link comprises a control link. 
     
     
       18. The computer program product of  claim 15 , wherein the link comprises a Media Access Control security (MACSec) link. 
     
     
       19. The computer program product of  claim 15 , wherein each of the network devices comprises a secure application entity (SAE), wherein the SAE runs a MACSec/QKD configuration software application that allows deployment of MACSec links with the quantum key distribution subsystem, and wherein the SAE comprises an application configured for exchanging the key identifiers, acquiring the quantum keys from the quantum key distribution subsystem using the key identifiers, and applying the quantum keys to the link between the SAEs. 
     
     
       20. The computer program product of  claim 15 , wherein the quantum key distribution subsystem comprises a key management entity (KME) configured for quantum key generation and distribution.

Join the waitlist — get patent alerts

Track US12438708B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.